Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-35154

Опубликовано: 09 июл. 2024
Источник: nvd
CVSS3: 7.2
EPSS Низкий

Описание

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote authenticated attacker, who has authorized access to the administrative console, to execute arbitrary code. Using specially crafted input, the attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 292641.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*
Версия от 8.5.0.0 (включая) до 8.5.5.25 (включая)
cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*
Версия от 9.0.0.0 (включая) до 9.0.5.20 (включая)

EPSS

Процентиль: 51%
0.00275
Низкий

7.2 High

CVSS3

Дефекты

CWE-250
NVD-CWE-Other

Связанные уязвимости

CVSS3: 7.2
github
больше 1 года назад

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote authenticated attacker, who has authorized access to the administrative console, to execute arbitrary code. Using specially crafted input, the attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 292641.

EPSS

Процентиль: 51%
0.00275
Низкий

7.2 High

CVSS3

Дефекты

CWE-250
NVD-CWE-Other